Practices for getting information from $_GET/$_POST and saving it to a database?

后端 未结 4 751
生来不讨喜
生来不讨喜 2021-01-24 21:23

What are today\'s best practises when it comes to getting information from a get/post and saving information to a database? Is data still escaped like it used to or are there ad

4条回答
  •  盖世英雄少女心
    2021-01-24 21:59

    Well it depends on what your values are and where they are coming from. The short and sweet answer is:

    ESCAPE AND SANITIZE

    which means make sure you put all strings in quotes and make sure you escape all special characters in user submitted strings. Type match and length check.

提交回复
热议问题